[feature] Harden maven verifier plugin against command injections #665
Labels
area:hardening
Issue related to security hardening
area:maven
An issue with the maven builder
type:feature
New feature request
Is your feature request related to a problem? Please describe.
The Maven slsa verifier plugin (slsa-framework/slsa-github-generator#2380) has a potential command injection when invoking the verifier.
Describe the solution you'd like
The plugin should be audited and hardened against command injections.
The text was updated successfully, but these errors were encountered: